What Security Controls Are Required for Today’s Cyber Insurance

Cyber-attacks are increasingly common. As a result, there are certain security controls underwriters expect Irish businesses to have in place to reduce the impact of a cyber incident. 

A rapidly escalating cyber threat landscape, driven by the growth of AI-powered phishing and ransomware, means cyber insurance in 2026 is a necessity, not an afterthought. As a result, insurers are tightening underwriting requirements, with most looking for proof that your security controls are both adequate and enforced.

But what are the cyber controls that underwriters expect Irish businesses to have in place? If you’re unsure what measures you should implement, this article explains what you can do to secure effective cover and what support you can expect if the worst happens. 

What security controls do cyber insurance providers expect? 

Most cyber security insurance providers expect businesses to demonstrate a basic level of cyber security, including some controls that are non-negotiable.  

This is due to a sustained increase in small business cyber threats including ransomware and business email incidents. IBM’s X-Force Threat Intelligence Index reveals a 40% increase in active ransomware groups compared to 2025 alone. As a result of this spike in AI-powered attacks, SMEs need to be prepared in case their own networks are targeted. 

Underwriters now expect businesses to have the following controls in place: 

Multi-Factor Authentication (MFA) – ensure MFA is in place across email, remote access and admin accounts. If MFA is available for cloud services and you haven’t implemented it, this could trigger an automatic failure.  

Backups – make sure you have encrypted backups, with multiple copies across different media, including one offline version. You should also implement a restoration testing schedule.  

Patching – ensure critical security updates are deployed regularly with clear visibility into any exceptions and why these occurred. 

Endpoint Detection and Response (EDR) – Basic antivirus protection is no longer sufficient. Underwriters expect managed and monitored EDR for every laptop or desktop, including for remote workers. Cover should provide central management, real-time alerts, and rapid containment. 

Email security – you may also need to demonstrate advanced email filtering and domain controls such as Domain-based Message Authentication, Reporting, and Conformance (DMARC) to block phishing, spoofing, and domain impersonation. 

In most cases, these controls are now essential. Many underwriters will expect to see proof that these controls are implemented, and failure to do so may lead to higher premiums, exclusions, or declined cover. Collect screenshots, reports, and evidence of configuration to simplify your application for cyber insurance cover. 

What can businesses expect from cyber insurance cover? 

 There are three main elements to cyber liability coverage: 

1) Financial cover for expenses incurred directly by your business while responding to an attack. 

2) Cover for actions that might be brought against you as a result of a data breach or other cyber event. This could include legal defence costs and compensation to others. 

3) Access to pre-vetted crisis management specialists and forensic investigators. 

Incident response support is particularly important because during an attack you may not have time to source specialist assistance. Instead, your insurer should provide a list of approved crisis management firms with cyber-specific expertise. 

To determine the scope and origin of the attack, your insurer may also help you to engage a forensic investigator, along with a crisis communications team to manage external messaging to customers or the media. 

During an attack, alert your insurer as soon as possible. This allows them to organise the correct resources at speed and keeps costs under control for both sides. 

What are the most common security gaps? 

No business intends to get caught out by cyber criminals, however many small to medium enterprises fall victim to an attack because they have overlooked basic precautions. Interestingly, there are some common gaps that can leave businesses exposed or prevent them from securing effective cover – and not all of them are related to IT security. 

Firstly, it’s common for staff to overestimate existing security measures. Secondly, staff need training to recognise and avoid evolving threats. Your employees are an important line of defence, yet 30% of Irish workers say they received no cybersecurity training in the past year.  

To protect against potential vulnerabilities, you need to think about both people and processes. Conduct regular security awareness training to educate staff about phishing challenges and create a documented incident response plan (IRP) that sets out who does what and when, including when to call your insurer. 

A slow response, including delayed incident reporting, is another common cybersecurity gap for SMEs and one that can cost more than you realise. 

Ready to reduce your risk and improve your cover? 

To ensure your next cyber liability insurance renewal goes ahead as planned, take a close look at your operations to identify any gaps. Fix the issues that matter most to insurers, whether that’s implementing basic security controls or introducing an incident response plan. 

Businesses that do so can reduce their premiums, improve policy terms, and strengthen their defences against today’s cyber threats.  

If you’re not sure what type of cyber insurance you need, talk to our liability experts to discover how OBF Insurance can keep your business safe from evolving cyber risks.